Privacy Policy
This policy explains what Marplio collects and stores, why it is used, and how it is managed.
Last updated: September 12, 2026Information we collect and store
When account features are used, we collect the display name, email address, and optional private full name you enter, or the name, email address, profile image, and authentication identifier provided by Google. The private full name is not used as a display name and may be used to prefill billing details only when you later choose to use the account holder as the billing party. Email-account passwords are stored only as non-reversible salted hashes, never as plaintext. If you enable optional multi-factor authentication, we store the TOTP secret and single-use recovery codes in encrypted form. We may store an IP address, user agent, token, cookie, and timestamps to manage sessions and trusted devices.
- Language preference cookie and account language
- Account status, plan, and feature-limit assignment history
- Account activation and first-Deck-save measurement events and delivery state
- Hashed anonymous export identifier, usage date, and successful export count
- Browser Markdown drafts, Decks saved to an account, and analytics preferences
- Google Slides scope, encrypted tokens, connection and revocation status, export jobs, and Google file identifiers
- Google Analytics usage data, including cookieless measurement before consent
- Server and proxy access or error logs
Markdown and generated files
Your Markdown is sent to the server to generate previews, PDFs, or PowerPoint files. Signed-out drafts are stored in localStorage and can be deleted from the same browser. When you sign in and save, the Deck title, Markdown, template, and update metadata are stored in the database and linked to your account. Generated PDF and PowerPoint files are not persisted as Deck data.
Cookies
We use cookies for language preferences, authentication sessions, and anonymous export limits. The raw anonymous export cookie is not stored in the database; its SHA-256 hash is stored. Language and anonymous export identifier cookies last for up to one year. If you consent to Google Analytics, Google uses analytics cookies such as _ga. Your analytics choice is stored in localStorage.
Analytics
We use Google Analytics to improve the service and understand usage. The Google tag loads when a page is displayed. Before a choice is made or when consent is denied, analytics_storage is denied and no analytics cookies are stored; Google may receive cookieless measurement signals including consent state, page URLs, referrers, browser and device information, and approximate location. Analytics cookies are used only after consent. In addition to page views, custom events measure the Home create action, use of the editor and preview, template switching, exports, Deck saves, signup and login starts, completed Google authentication, successful email login, account activation, the first Deck save, Home news use, views, clicks, and dismissals of the free-account promotion, and the selected service-sharing method. To reduce missing or duplicate account-activation and first-save events, Marplio stores their delivery state with the account and sends only fixed event names from the user’s browser. Event values are limited to template identifiers, published release identifiers, anonymous or authenticated state, PDF or PPTX format, fixed failure categories, save operations, authentication methods, the page where Google authentication started, and the fixed placement of the free-account promotion. Sharing sends only a fixed event name, not the shared URL or post text. We do not send Markdown, Deck titles or IDs, project names, file names, URL queries, contact messages, names, email addresses, internal user IDs, OAuth IDs, plan or payment information, or free-form error details to Google Analytics. You can change your choice through Analytics settings in the footer.
Contact information
The contact form collects your name, email address, inquiry type, subject, and message and sends them to the operator’s email inbox. Marplio does not currently store form submissions in its database. Received email is retained as needed to respond, protect rights, prevent abuse, and meet legal obligations.
Purposes
- Providing the service, authentication, session continuity, and Deck storage
- Generating previews and exports and enforcing usage limits
- Troubleshooting, security, and abuse prevention
- Responding to inquiries, improving the service, and meeting legal obligations
Services and sharing
Google OAuth or email authentication is used when you sign in. Only when you save to Google Slides, Marplio asks for the additional `drive.file` scope, which permits access to files created or selected by Marplio. Markdown, images, and the title are sent to Google to create a Presentation in your Google Drive. Connection tokens are stored encrypted, and you can disconnect from Settings. To check a new or changed password against known breach data, Marplio sends only the first five characters of its SHA-1 hash—not the password itself—to Have I Been Pwned. Google Analytics is used for analytics. Choosing a share action opens the X or Threads composer or your device share sheet and passes fixed copy with the public Home URL. Marplio does not post automatically, and you can review the content before posting. The destination provider processes information under its own policy. When you make a development support payment, you leave Marplio for a Stripe-hosted payment page. Stripe collects information such as your name, email address, payment amount and currency, payment status, and payment identifier, and may make some of it available to the operator in the Stripe Dashboard. Stripe or the operator retains this information as needed for payment records, inquiries and refunds, fraud prevention, and legal obligations. Marplio does not collect or store card numbers. We may also use providers for hosting, databases, and monitoring. We do not sell personal data or disclose it to third parties without consent, except as required by law.
Security and retention
We apply safeguards appropriate to the data, including encrypted transport, environment-based secret management, separated database privileges, and encrypted authentication tokens. Information is retained as needed for its purpose, security, and legal obligations, then deleted when no longer necessary.
Access, correction, and deletion
Use the Contact page to request notice of purpose, access, correction, suspension, or deletion of retained personal data. We will verify your identity and respond under applicable law.
Changes
We may update this policy as features or laws change. Material changes will be announced through the service.